Appraisal certification system, program, and appraisal certification method
Patent Information
- Application Number
- JP2026088763
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2026-05-27
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2046-05-27
Smart Images

Figure 0007909347000001_ABST
Abstract
Description
Technical Field
[0008] ,
[0001] The present disclosure relates to an authentication system, a program, and an authentication method.
Background Art
[0002] In recent years, not only assets that are physical objects such as products, parts, equipment, documents, and other tangible things, but also assets that are intangible things such as software, digital content, design data, right information, qualification information, and other intangible assets, the importance of technologies for confirming their authenticity, origin, ownership, or usage rights has been increasing.
[0003] In addition, for composite assets in which physical assets and intangible assets are associated, and composite assets that include or reference a plurality of constituent assets, it is required to confirm not only the authenticity of each individual constituent asset but also the relationships between the constituent assets in an integrated manner.
[0004] Conventionally, in authenticity determination, technologies for specifying an asset to be authenticated or its related records using product - side identifiers, transaction hashes, two - dimensional codes, contract addresses, token IDs, and other identification elements are known.
[0005] Also, as a backing for authenticity determination, technologies using wallet information, decentralized identifiers, verifiable credentials, signature data, external record references, warranty information, and other evidence elements are known.
[0006] Furthermore, technologies for determining authenticity by referring to information recorded in a distributed ledger, an external database, an external record storage location, or other record locations are known.
[0007] Since the types of assets to be authenticated, available identification elements, available evidence elements, available record locations, and the aspects of authentication requirements are not uniform, there may be a case where a configuration that implements multiple types of authenticity processing within the same system and uses them appropriately according to individual authentication requirements is required.
[0008] However, conventional technologies have not adequately considered configurations that, when multiple authenticity processing candidates coexist, technically select which authenticity processing candidates to combine for authenticity determination, and perform processing while suppressing the execution of the unselected authenticity processing candidates.
[0009] In recent years, technologies have become known that use artificial intelligence (AI) models to analyze fraud risk, anomaly, or reliability based on input information such as the source of the appraisal request, the frequency of the request, and past judgment history.
[0010] However, a configuration that directly reflects the results of AI analysis in selecting multiple authenticity processing candidates or suppressing the execution of non-selected candidates, and constructs a sequence of authenticity processing candidates for each appraisal request, has not yet been sufficiently established.
[0011] Zero-knowledge proofs are known as a technique that demonstrates ownership, possession, validity of credentials, possession of a signing key, and other similar facts without disclosing the confidential information itself.
[0012] However, depending on the risk category of the appraisal request, a configuration that incorporates zero-knowledge proof acquisition and zero-knowledge proof verification processes into the authenticity processing candidate column, instead of the evidence acquisition process that directly obtains wallet information, verifiable credentials, or signature data, has not been sufficiently considered.
[0013] A technology is known that uses digital image information, or digital twin information, associated with tangible assets, to manage the state, attributes, or provenance of physical objects.
[0014] Furthermore, there are known technologies that use token reference information corresponding to real-world assets (RWAs) to associate physical or composite assets with digital reference objects.
[0015] However, in the case of composite assets, there is still room for improvement in the configuration for verifying the consistency of physical identification information, digital twin information, and token reference information corresponding to real-world assets as part of the authenticity processing candidate sequence.
[0016] To mitigate the risk of decryption by quantum computers, signature generation or signature verification techniques using quantum-resistant cryptography are known.
[0017] However, configurations that selectively incorporate signature verification processing using quantum computation-resistant cryptography into the authenticity processing candidate sequence, depending on the quantum computation threat classification, have not been sufficiently considered.
[0018] Techniques are known for generating authentication information based on key materials shared through a quantum key distribution session, or for generating reference information corresponding to said quantum key distribution session.
[0019] However, the configuration for incorporating candidates for evidence acquisition processing or reference generation processing into the authenticity processing candidate sequence based on quantum key distribution session establishment information or corresponding session identification information has not been adequately clarified.
[0020] A technique is known that involves reviewing cryptographic schemes or verification procedures in response to updates to threat information or cryptographic scheme transition condition information related to quantum computers.
[0021] However, a configuration that regenerates authenticity execution procedure data and records the identification information of the authenticity execution procedure data before and after the update in the audit record, when an update to quantum computing threat classification information or cryptographic method transition condition information is detected, has not yet been sufficiently established. [Prior art documents] [Patent Documents]
[0022] [Patent Document 1] Japanese Patent Publication No. 2021-28824 [Patent Document 2] Japanese Patent Application Laid-Open No. 2001-357377 [Patent Document 3 International Publication No. 2014 / 207890 [Patent Document 4 Japanese Patent Application Laid-Open No. 2020-35197 [Patent Document 5 Japanese Patent No. 6894033 [Patent Document 6 International Publication No. 2020 / 080537 [Non-Patent Document
[0023] [Non-Patent Document 1 Trusted Web White Paper Ver2.0 [Non-Patent Document 2 W3C Verifiable Credentials Data Model v2.0 [Non-Patent Document 3 FIPS 204, Module-Lattice-Based Digital Signature Standard [Non-Patent Document 4 ETSI GS QKD 004, Quantum Key Distribution; Application Interface [Summary of the Invention [Problems to be Solved by the Invention
[0024] Patent Documents 1 to 6 describe techniques for verifying authenticity, legitimacy, rights relationships, or recorded content using objects, target data, identification information, authentication information, external records, or ledger records, etc.
[0025] However, a configuration that identifies a candidate authenticity processing column from an authenticity processing candidate table and a candidate processing connection relationship table based on an execution context including identification elements, evidence elements, recording destination, asset type information, and input information relating to the appraisal request for the asset subject to appraisal, and generates authenticity execution procedure data indicating the said authenticity processing candidate column, as in the present invention, is not sufficiently disclosed in Patent Documents 1 to 6.
[0026] Furthermore, a configuration that identifies a sequence of authenticity processing candidates, including zero-knowledge proof acquisition processing candidates and zero-knowledge proof verification processing candidates, instead of an evidence acquisition processing candidate that directly acquires wallet information, verifiable credentials, or signature data according to the appraisal request risk classification information, as in the present invention, is not sufficiently disclosed in Patent Documents 1 to 6.
[0027] Furthermore, configurations that identify candidate sequences for authenticity processing or regenerate authenticity execution procedure data according to quantum computation threat classification information, quantum key distribution session establishment information, session identification information, or cryptographic scheme transition condition information, as in the present invention, are not sufficiently disclosed in Patent Documents 1 to 6.
[0028] Furthermore, a configuration that controls the processing path for each appraisal request in an auditable manner by setting the state of the execution control table corresponding to authenticity processing candidates not included in the authenticity execution procedure data to a non-execution state, and executing only the selected authenticity processing candidates according to the authenticity execution procedure data, as in the present invention, is not sufficiently disclosed in Patent Documents 1 to 6.
[0029] Conventionally, techniques for determining the authenticity of an asset subject to appraisal have been known, including those using identifiers, signature data, credentials, external records, and other information. However, the types of assets subject to appraisal, the nature of appraisal requests, the available information, and the available record locations are not uniform.
[0030] Therefore, in a configuration that always applies the same processing route to the same appraisal request, processing that is not suitable for the appraised asset or appraisal request may be executed, potentially reducing the efficiency, reproducibility, and appropriateness of authenticity determination.
[0031] In particular, when multiple authenticity processing candidates are available, executing the process without technically identifying the appropriate sequence of authenticity processing candidates based on the available identification elements, evidence elements, and recording destination may result in unnecessary processing being initiated or necessary processing being omitted.
[0032] Furthermore, some appraisal requests pose a higher risk of misuse, impersonation, unauthorized access, or information leakage compared to ordinary appraisal requests. However, conventional technologies do not adequately configure the authenticity processing candidate sequence to switch according to the risk level of the appraisal request.
[0033] Furthermore, configurations that directly obtain wallet information, verifiable credentials, or signature data have the problem that confidential or highly confidential information may be excessively exposed, even when the risk of authentication requests is high.
[0034] Furthermore, when dealing with tangible assets, intangible assets, or composite assets, it is necessary to consider not only the authenticity of a single asset, but also the relationships between constituent assets, the consistency of physical identification information, digital image information, and token reference information corresponding to real-world assets. However, conventional technology does not adequately control the processing candidate sequence to appropriately reflect these differences in asset types.
[0035] In addition, with the emergence of threats originating from quantum computers, verification using quantum-resistant cryptography and the use of authentication or reference information based on quantum key distribution sessions may be required. However, conventional technologies do not have a sufficiently established configuration for regenerating authenticity execution procedure data in response to updates to quantum threat classification information or cryptography transition condition information.
[0036] Furthermore, when asset relationships are updated, such as through integration, separation, exchange, addition, or reference, or other relationship changes occur, there is insufficient infrastructure to regenerate authenticity execution procedure data based on the updated execution context and to record the relationships before and after regeneration in a traceable manner.
[0037] The present invention has been made in view of the above problems, and aims to provide an appraisal certification system, program, and appraisal certification method that can appropriately identify a sequence of authenticity processing candidates according to the risk level of the appraisal request, the asset type of the asset to be appraised, available identification elements, evidence elements, and recording destination, set unnecessary authenticity processing candidates to a non-executable state, execute only the selected authenticity processing candidates to perform an authenticity determination, and record the results as an audit record. [Means for solving the problem]
[0038] An appraisal and certification system according to one aspect of the present invention stores an authenticity processing candidate table, a candidate processing connection relationship table, and an execution control table, and acquires an execution context that includes identification elements, evidence elements, recording destination, asset type information, and input information related to the appraisal request for the asset to be appraised.
[0039] The appraisal certification system calculates appraisal request risk classification information using an artificial intelligence (AI) model based on the input information relating to the appraisal request, and identifies authenticity processing candidate columns that include authenticity processing candidates belonging to at least the identification acquisition stage, evidence acquisition stage, verification stage, and result recording stage, and that satisfy the application condition information, based on the execution context, the appraisal request risk classification information, the authenticity processing candidate table, and the candidate processing connection relationship table.
[0040] The authentication certification system generates authenticity execution procedure data indicating the authenticity processing candidate column, sets the state of the execution control table corresponding to the authenticity processing candidate included in the authenticity execution procedure data to an executable state, and sets the state of the execution control table corresponding to the authenticity processing candidate not included in the authenticity execution procedure data to a non-executable state.
[0041] The authentication certification system performs an authenticity determination by executing only the authenticity processing candidates set to the executable state according to the authenticity execution procedure data, and records the identification information of the authenticity execution procedure data and the result of the authenticity determination as an audit record.
[0042] In one embodiment, the authenticity processing candidate table includes zero-knowledge proof acquisition processing candidates and zero-knowledge proof verification processing candidates, and when the appraisal request risk classification information indicates a high-risk classification, the authenticity processing candidate column including the zero-knowledge proof acquisition processing candidate and the zero-knowledge proof verification processing candidate is identified instead of the evidence acquisition processing candidate that directly acquires wallet information, verifiable credentials, or signature data.
[0043] In one embodiment, when the asset to be appraised is a composite asset and the execution context includes physical asset-corresponding digital mapping information and token reference information corresponding to a real-world asset, a sequence of authenticity processing candidates is identified, which includes authenticity processing candidates that verify the consistency of the physical-side identification information, the digital mapping information, and the token reference information.
[0044] In one embodiment, the authenticity processing candidate table includes signature verification processing candidates using quantum computation-resistant cryptography, and when the execution context includes quantum computation threat classification information, the authenticity processing candidate column including the signature verification processing candidate is identified according to the quantum computation threat classification information.
[0045] In one embodiment, the authenticity processing candidate table includes evidence acquisition processing candidates or reference generation processing candidates based on a quantum key distribution session, and when the execution context includes quantum key distribution session establishment information or corresponding session identification information, the authenticity processing candidate column including the evidence acquisition processing candidate or the reference generation processing candidate is identified based on that information.
[0046] In one embodiment, if the execution context includes quantum computation threat classification information or cryptographic scheme transition condition information as threat information originating from a quantum computer, new authenticity execution procedure data is regenerated in accordance with the update of such information, and the identification information of the authenticity execution procedure data before and after the update is associated and recorded in the audit record.
[0047] In one embodiment, the authenticity determination includes multi-signature authentication based on the alignment or correspondence of at least two authentication elements selected from at least a portion of the identification elements and evidence elements, wherein at least one of the authentication elements may be an authentication element to which third-party authentication has been granted.
[0048] According to the present invention, the authenticity processing candidate column can be appropriately identified based on the appraisal request risk classification information derived from the input information relating to the appraisal request and the execution context relating to the asset to be appraised.
[0049] Furthermore, by setting the unselected authenticity processing candidates to a non-executable state and allowing only the selected authenticity processing candidates to run in an executable state, it is possible to suppress the execution of unnecessary processes and improve the consistency and reproducibility of authenticity determination.
[0050] Furthermore, in high-risk categories, by selecting a list of authenticity processing candidates that includes zero-knowledge proof acquisition processing candidates and zero-knowledge proof verification processing candidates, it is possible to perform the necessary proof for authenticity determination while suppressing excessive disclosure of confidential information.
[0051] Furthermore, by verifying the consistency of physical identification information, digital image information, and token reference information corresponding to real-world assets for composite assets, it is possible to appropriately perform authenticity determination for a wide range of asset types, including tangible assets, intangible assets, and composite assets.
[0052] Furthermore, by incorporating candidate signature verification processes using quantum-resistant cryptography and candidate processes based on quantum key distribution sessions into the authenticity process candidate sequence, it becomes possible to flexibly respond to threats originating from quantum computers.
[0053] Furthermore, by regenerating authenticity execution procedure data in response to quantum computing threat classification information, cryptographic method transition condition information, or asset relationship update information, and by associating the identification information before and after the update and retaining it in the audit record, it becomes possible to track the change history and reconstruction history of the authenticity determination process.
[0054] Furthermore, the reliability of authenticity determination can be improved by using multi-signature authentication based on multiple authentication elements selected from at least some of the identification and evidence elements.
[0055] Therefore, according to the present invention, a wide range of assets subject to appraisal, including tangible assets, intangible assets, and composite assets, can be managed in an auditable manner while switching the processing necessary for determining authenticity according to the circumstances. [Brief explanation of the drawing]
[0056] [Figure 1] This is an explanatory diagram showing an example of the overall configuration of the appraisal and certification system. [Figure 2] This is an explanatory diagram showing an example of a candidate table for authenticity processing. [Figure 3] This is an explanatory diagram showing an example of a candidate processing connection relationship table. [Figure 4] This is an explanatory diagram showing an example of an execution control table. [Figure 5] This is an explanatory diagram showing an example of an execution context. [Figure 6] This is an explanatory diagram showing an example of authenticity execution procedure data. [Figure 7] This is an explanatory diagram showing an example of an audit record. [Figure 8] This is an explanatory diagram showing the basic processing flow of the appraisal and certification system. [Figure 9]This is an explanatory diagram showing the process flow for identifying candidate sequences for authenticity processing and generating authenticity execution procedure data. [Figure 10] This is an explanatory diagram illustrating the process flow for setting non-selected authenticity processing candidates to a non-executable state. [Figure 11] This diagram illustrates the process flow for determining authenticity by executing only the selected authenticity processing candidates. [Figure 12] This is an explanatory diagram showing the process flow for generating audit records based on authenticity execution procedure data and authenticity determination results. [Figure 13] This diagram illustrates the process flow for identifying candidate sequences of authenticity processing, including candidates for zero-knowledge proof acquisition and zero-knowledge proof verification, when the risk category is high. [Figure 14] This diagram illustrates the process flow for verifying the consistency between digital mapping information corresponding to physical assets and token reference information corresponding to real-world assets for a composite asset. [Figure 15] This diagram illustrates the process flow for regenerating authenticity execution procedure data and recording the reconstruction history in response to updates to asset relationships. [Figure 16] This diagram illustrates the process flow for identifying a sequence of authenticity processing candidates, including signature verification processing candidates using quantum computation-resistant cryptography. [Figure 17] This diagram illustrates the process flow for identifying a sequence of authenticity processing candidates, including candidates for evidence acquisition or reference generation based on a quantum key distribution session. [Figure 18] This diagram illustrates the process flow for regenerating authenticity execution procedure data in response to updates to threat information or cryptographic method transition condition information related to quantum computers. [Figure 19] This is an explanatory diagram showing the flow of the non-execution state setting process when it is not possible to construct a candidate sequence for authenticity processing. [Figure 20] This is an explanatory diagram showing an embodiment including an authentication element 119, multi-signature authentication 120, and third-party authentication 121. [Modes for carrying out the invention]
[0057] (Definition of terms) In this specification, "asset" means a tangible asset, an intangible asset, or a composite asset.
[0058] In this specification, “tangible asset” means an asset that has a physical shape or structure and is subject to possession, storage, transfer, use, repair, replacement, recovery, or disposal.
[0059] In this specification, “intangible asset” means an asset that does not have a physical form but is subject to identification, recording, reference, transfer, use, verification or evaluation, and has value, rights, attributes, state or provenance.
[0060] In this specification, "composite asset" means an asset that includes or references two or more component assets.
[0061] In this specification, “component asset” means an asset that constitutes a composite asset or is referenced by said composite asset, and may be a tangible asset, an intangible asset, or another composite asset.
[0062] In this specification, "asset subject to appraisal" means an asset that is subject to authenticity determination, and may be a tangible asset, an intangible asset, or a composite asset.
[0063] In this specification, “identifying element” means information used to identify the asset being appraised, its constituent assets, related records, references, or correspondences.
[0064] In this specification, “evidence” means information used to prove or authenticate authenticity, ownership, possession, qualification, provenance, signature, or other relevant information.
[0065] In this specification, “recording location” means a location where information related to the appraised asset or authenticity determination is recorded, held, or referenced.
[0066] In this specification, "asset type information" refers to information indicating whether the asset being appraised is a tangible asset, an intangible asset, or a composite asset, and, in the case of a composite asset, information indicating the constituent relationships.
[0067] In this specification, "input information relating to the appraisal request" refers to the source of the appraisal request, the frequency of appraisal requests, past authenticity determination history, past audit records, and other input information relating to the appraisal request.
[0068] In this specification, "appraisal request risk classification information" refers to information indicating the degree of risk or handling classification of an appraisal request, based on the input information related to the appraisal request.
[0069] In this specification, "applicable conditions information" means that the authenticity processing candidate is For use in determining the authenticity of the appraised asset This refers to information indicating conditions, which may include conditions regarding the appraisal request risk category, asset type, encryption conditions, available information, or available record locations.
[0070] In this specification, "authenticity processing candidate" means a specific processing unit that may be selected for determining the authenticity of the asset being appraised.
[0071] In this specification, "authenticity processing candidate sequence" means a processing sequence in which one or more authenticity processing candidates are connected in a predetermined order.
[0072] In this specification, "authenticity execution procedure data" means data indicating candidate columns for authenticity processing, and may include at least candidate identifier columns, execution order, and identification information contained in said candidate columns for authenticity processing.
[0073] In this specification, "audit record" refers to information recorded by associating identification information of authenticity execution procedure data with the results of authenticity determination.
[0074] In this specification, "non-executable data" means information indicating that the authenticity determination has been set to a non-executable state due to the inability to form a candidate column for authenticity processing or for other reasons.
[0075] In this specification, "reconstruction history" refers to information that shows the relationship between the identification information of the authentic execution procedure data before and after its regeneration, when the authentic execution procedure data is regenerated in response to an update of the execution context.
[0076] In this specification, “authentication element” means an element selected from at least some of the identification element and evidence element and used in multi-signature authentication.
[0077] In this specification, "multi-signature authentication" means authentication that is established based on the alignment or correspondence of at least two of multiple authentication factors.
[0078] In this specification, "third-party certification" means certification or assurance granted by a third party to an authentication element.
[0079] In this specification, "quantum computing threat classification information" refers to information indicating the degree of threat caused by quantum computers or the need for a transition to a new cryptographic scheme.
[0080] In this specification, "quantum computation-resistant cryptography (PQC)" refers to cryptographic schemes that are resistant to the risk of decryption by quantum computers.
[0081] In this specification, "quantum key distribution (QKD) session" means a session in which key material is shared by quantum key distribution, and may include information about the establishment or identification of such session.
[0082] In this specification, "physical identification information" means identification information corresponding to a tangible asset, which includes at least one of the following identifiers: product identifier, serial number, part number, lot number, or other similar identifier.
[0083] In this specification, "digital image information corresponding to a physical asset (digital twin information)" means digital image information associated with a tangible asset, which represents at least one of the following: the asset's composition, state, attributes, provenance, inspection results, or update history.
[0084] In this specification, "Token reference information corresponding to a real-world asset (RWA)" means reference information to a token or related record corresponding to the asset being appraised or its constituent assets, and includes at least one of the following: token ID, contract address, or transaction hash.
[0085] In this specification, "cryptographic scheme transition condition information" means information that indicates at least one of the following: reaching a predetermined quantum computing threat category, reaching a predetermined time, receiving a predetermined external notification, updating policy information at a predetermined recording location, or entering a predetermined administrator information, and is used to determine the transition of the cryptographic scheme.
[0086] In this specification, "authentication information" means information generated based on key material shared in a quantum key distribution session, or generated by other authentication means, which is used as evidence for determining authenticity.
[0087] Figure 1 is an explanatory diagram showing an example of the overall configuration of the appraisal and certification system 1 according to this embodiment. The appraisal and certification system 1 includes at least a terminal 2, an asset to be appraised 5, a public communication network 10, and a recording destination.
[0088] The asset to be appraised (5) may be a tangible asset, an intangible asset, or a composite asset. If it is a composite asset, the asset to be appraised (5) may include or refer to two or more component assets, which may be tangible assets, intangible assets, or other composite assets.
[0089] Terminal 2 is a device operated by the appraiser, and is used to input or display identification elements, evidentiary elements, asset type information, or input information related to the appraisal request for the asset 5. Terminal 2 may be a smartphone, tablet, personal computer, dedicated terminal, reader, or similar information processing device.
[0090] The public communication network 10 is a communication channel for sending and receiving information between the terminal 2 and the authentication certification system 1, and between the authentication certification system 1 and each recording destination. The public communication network 10 may include the Internet, a mobile communication network, a dedicated communication network, or a combination thereof.
[0091] The authentication and certification system 1 comprises a processor 80 and a storage unit 110. The processor 80 functions as one of the functional units described later by executing programs stored in the storage unit 110. The storage unit 110 may include at least one of a main memory and an auxiliary memory.
[0092] Functionally, the processor 80 may function as an execution context acquisition unit 81, an appraisal request risk classification calculation unit 82, an authenticity processing candidate sequence identification unit 83, an execution control unit 84, and an audit record unit 85. Each of these units may be implemented by a single processor 80 or distributed across multiple processors.
[0093] The execution context acquisition unit 81 acquires identification elements, evidence elements, recording destination, asset type information, and input information related to the appraisal request for the asset 5 to be appraised, and generates an execution context 114.
[0094] The appraisal request risk classification calculation unit 82 calculates appraisal request risk classification information using an artificial intelligence (AI) model based on the input information related to the appraisal request.
[0095] The authenticity processing candidate column identification unit 83 identifies candidate columns for authenticity processing based on the authenticity processing candidate table 111, the candidate processing connection relationship table 112, the execution context 114, and the appraisal request risk classification information, and generates authenticity execution procedure data 115.
[0096] The execution control unit 84 sets the state of the execution control table 113 corresponding to the authenticity processing candidate included in the authenticity execution procedure data 115 to an executable state, and sets the state of the execution control table 113 corresponding to the authenticity processing candidate not included in the authenticity execution procedure data 115 to a non-executable state. Furthermore, the execution control unit 84 executes only the authenticity processing candidate that has been set to an executable state, in accordance with the authenticity execution procedure data 115.
[0097] The audit recording unit 85 generates an audit record 116 by associating the identification information of the authenticity execution procedure data 115 with the result of the authenticity determination, and records it in the storage unit 110 or each recording destination. If necessary, the audit recording unit 85 may generate non-execution status data 117 and reconstruction history 118 and record them in association with the audit record 116.
[0098] The recording destination may include an external database 8a, a distributed file server 8b, a distributed ledger 8c, or other information storage locations. The above recording destinations may be used individually or in combination.
[0099] The external database 8a is used to record the asset under appraisal 5, component assets, authenticity determination history, authentication information, or related metadata. The distributed file server 8b may be used to hold evidence data, reference data, authentication data, and other relatively large amounts of information. The distributed ledger 8c may be used to record identification information, reference information, token reference information, certification results, and other information requiring traceability.
[0100] If the asset to be appraised 5 is a composite asset, the appraisal certification system 1 may acquire the relationship between the parent asset and the child asset, or the pre-integration asset and the post-integration asset, or the pre-separation asset and the post-separation asset, as updated asset relationship information, and use it to generate the authenticity execution procedure data 115 or the reconstruction history 118 described later.
[0101] Figure 2 is an explanatory diagram showing an example of the authenticity processing candidate table 111. The authenticity processing candidate table 111 records the candidate identifier, processing stage, request input type, generated output type, and applicable condition information associated with each authenticity processing candidate.
[0102] The processing steps may include at least an identification step, an evidence acquisition step, a verification step, and a results recording step. It may also include a reference generation step, if necessary. The reference generation step may be selected if an available recording destination exists.
[0103] The candidate identifier is information that identifies each authenticity processing candidate. The requested input type indicates the type of input information required prior to the execution of the authenticity processing candidate. The generated output type indicates the type of output information obtained by the execution of the authenticity processing candidate. The applicable conditions information may indicate conditions regarding the appraisal request risk category, asset type, encryption conditions, available information, or available recording destinations.
[0104] Examples of authenticity processing candidates may include product-side identifier acquisition candidates, transaction hash acquisition candidates, two-dimensional code acquisition candidates, wallet information acquisition candidates, verifiable credential acquisition candidates, signature data acquisition candidates, zero-knowledge proof acquisition candidates, zero-knowledge proof verification candidates, signature verification processing candidates using quantum computation-resistant cryptography, evidence acquisition processing candidates based on quantum key distribution sessions, reference generation processing candidates corresponding to quantum key distribution sessions, consistency verification processing candidates between physical-side identification information and digital twin information, and result recording processing candidates.
[0105] Figure 3 is an explanatory diagram showing an example of a candidate processing connection relationship table 112. The candidate processing connection relationship table 112 indicates whether a connection is possible between the generated output type of the preceding authenticity processing candidate and the requested input type of the succeeding authenticity processing candidate. The connection status may be expressed, for example, as "connectable" or "not connectable".
[0106] The candidate processing connection relationship table 112 may record information such as the preceding candidate identifier, the succeeding candidate identifier, whether connection is possible, connection conditions, and other information. The authenticity processing candidate column identification unit 83 determines whether the output of the preceding authenticity processing candidate can be used as input for the succeeding authenticity processing candidate by referring to the candidate processing connection relationship table 112.
[0107] Figure 4 is an explanatory diagram showing an example of an execution control table 113. The execution control table 113 indicates whether each authenticity processing candidate is in an executable state or a non-executable state. The executable state and non-executable state may be recorded as an execution flag, permission information, startup state information, or other control information.
[0108] The execution control unit 84 sets the state of the execution control table 113 corresponding to the authenticity processing candidate included in the authenticity execution procedure data 115 to an executable state, and sets the state of the execution control table 113 corresponding to the authenticity processing candidate not included in the authenticity execution procedure data 115 to a non-executable state. As part of setting to a non-executable state, API call permission information may be disabled, execution flags may be disabled, container startup permission information may be blocked, or function call destination control information may be rewritten.
[0109] Figure 5 is an explanatory diagram showing an example of an execution context 114. The execution context 114 includes identification elements, evidence elements, recording destination, asset type information, and input information related to the appraisal request for the asset 5 to be appraised.
[0110] Identification elements may include product identifiers, transaction hashes, QR codes, contract addresses, token IDs, and other identifying information. Evidence elements may include wallet information, decentralized identifiers, verifiable credentials, signature data, external record references, guarantee information, and other information used for verification or authentication.
[0111] The asset type information may indicate whether the asset subject to appraisal 5 is a tangible asset, an intangible asset, or a composite asset. If it is a composite asset, the asset type information may include component assets, parent asset information, child asset information, pre-integration asset information, post-integration asset information, pre-separation asset information, or post-separation asset information.
[0112] The input information for the appraisal request may include information identifying the source of the appraisal request, information on the frequency of appraisal requests, information on past authenticity determination history, data on non-execution status included in past audit records, and other information. The appraisal request risk classification calculation unit 82 may calculate the appraisal request risk classification information based on this information.
[0113] Furthermore, the execution context 114 may include quantum computation threat classification information, quantum key distribution session establishment information, session identification information, physical asset-corresponding digital mapping information (digital twin information), token reference information corresponding to real-world assets, and other information.
[0114] Figure 6 is an explanatory diagram showing an example of authenticity execution procedure data 115. Authenticity execution procedure data 115 is data that shows candidate columns for authenticity processing and includes at least a candidate identifier column, execution order, and identification information.
[0115] Furthermore, the authenticity execution procedure data 115 may, as necessary, include information on usage identification elements, usage evidence elements, usage record destination, applied appraisal request risk classification information, asset type information, cryptographic condition information, or combination information of authentication elements.
[0116] Figure 7 is an explanatory diagram showing an example of an audit record 116. The audit record 116 records the identification information of the authenticity execution procedure data 115, the candidate identifier column contained in the authenticity execution procedure data 115, the expert opinion request risk category information, the identification elements, evidence elements or reference information used in the authenticity determination, and the results of the authenticity determination in relation to each other.
[0117] The audit record 116 may include, if necessary, associated non-execution status data 117 and reconstruction history 118. The non-execution status data 117 indicates that the authenticity determination has been set to a non-execution state due to the inability to form an authenticity processing candidate column or other reasons. The reconstruction history 118 shows the relationship between the identification information of the authenticity execution procedure data 115 before and after regeneration when the authenticity execution procedure data 115 is regenerated in response to an update of the execution context 114.
[0118] As described above, in this embodiment, by appropriately structuring the overall system configuration of the appraisal certification system 1, the authenticity processing candidate table 111, the candidate processing connection relationship table 112, the execution control table 113, the execution context 114, the authenticity execution procedure data 115, the audit record 116, the non-execution status data 117, and the reconstruction history 118, it is possible to control the authenticity processing candidate column according to the content of the appraisal request and the characteristics of the appraisal target asset 5.
[0119] The basic operation of the appraisal and certification system 1 according to this embodiment, as well as embodiments of the identification elements, evidence elements, and recording destinations, will be described below with reference to Figures 8 to 19.
[0120] The appraisal certification system 1 obtains an execution context 114 related to the asset to be appraised 5 based on input from terminal 2 or information obtained from each recording location. The execution context 114 includes identification elements, evidence elements, recording locations, asset type information, and input information related to the appraisal request.
[0121] The execution context acquisition unit 81 acquires asset type information indicating whether the asset to be appraised 5 is a tangible asset, an intangible asset, or a composite asset. If the asset to be appraised 5 is a composite asset, further information regarding component assets, parent asset information, child asset information, and other asset relationships may be acquired.
[0122] The appraisal request risk classification calculation unit 82 calculates appraisal request risk classification information using an artificial intelligence (AI) model based on the appraisal request source identification information, appraisal request frequency information, past authenticity determination history information, non-execution status data included in past audit records, and other input information.
[0123] The authenticity processing candidate column identification unit 83 refers to the authenticity processing candidate table 111 shown in Figure 2 and the candidate processing connection relationship table 112 shown in Figure 3, and identifies authenticity processing candidate columns that include authenticity processing candidates belonging to at least the identification acquisition stage, evidence acquisition stage, verification stage and result recording stage, and that satisfy the application condition information, according to the execution context 114 and the appraisal request risk classification information.
[0124] The authenticity processing candidate sequence identification unit 83 confirms the connection relationship between the generated output type of the preceding authenticity processing candidate and the requested input type of the succeeding authenticity processing candidate, thereby constructing an authenticity processing candidate sequence from only connectable authenticity processing candidates. This ensures that the preceding and succeeding processes can be incorporated into the same authenticity processing candidate sequence only when the output of the preceding process can be used as input for the succeeding process.
[0125] The authenticity processing candidate sequence identification unit 83 generates authenticity execution procedure data 115 based on the identified authenticity processing candidate sequence. The authenticity execution procedure data 115 includes at least a candidate identifier sequence, execution order, and identification information, and may further include information on the identification elements, evidence elements, recording destination, or authentication elements used, as necessary.
[0126] The execution control unit 84 sets the state corresponding to the authenticity processing candidate included in the authenticity execution procedure data 115 to an executable state in the execution control table 113 shown in Figure 4, and sets the state corresponding to the authenticity processing candidate not included in the authenticity execution procedure data 115 to a non-executable state.
[0127] As part of setting the system to the non-execution state described above, the execution control unit 84 may perform at least one of the following actions: invalidating API call permission information, invalidating the execution flag, blocking container startup permission information, or rewriting function call destination control information. Specifically, if the system is built with a microservice architecture or container virtualization technology (such as Kubernetes), "blocking container startup permission information" means setting the number of execution replicas in the startup manifest of the container (Pod) corresponding to the authenticity processing candidate set to the non-execution state to zero, or rewriting the routing rules of the service mesh to block communication traffic to the container. Furthermore, "rewriting function call destination control information" means changing the reference destination of the dynamic linker or function pointer in the program from the original processing logic to the address of a stub function (dummy function) that returns exception handling (error response). In addition, if a distributed ledger 8c (smart contract) is used as the recording destination, the system may include a process to restrict the execution (call) of a non-execution state function using an on-chain modifier (Mo diffier), and to revert the transaction if it is called. This technically prevents the activation of unselected authenticity processing candidates.
[0128] The execution control unit 84 sequentially executes only the authenticity processing candidates set to an executable state according to the authenticity execution procedure data 115, and performs authenticity determination. Figure 11 is a flowchart showing an example of this authenticity determination process.
[0129] If the appraisal request risk classification information indicates a high-risk classification, the authenticity processing candidate sequence identification unit 83 may identify an authenticity processing candidate sequence that includes a zero-knowledge proof acquisition processing candidate and a zero-knowledge proof verification processing candidate, as shown in Figure 13, instead of an evidence acquisition processing candidate that directly acquires wallet information, verifiable credentials, or signature data.
[0130] If the asset to be appraised 5 is a composite asset and digital image information corresponding to the physical asset and token reference information corresponding to the real-world asset are available, the authenticity processing candidate sequence identification unit 83 may identify an authenticity processing candidate sequence that includes an authenticity processing candidate that verifies the consistency of the physical identification information, the digital image information, and the token reference information, as shown in Figure 14.
[0131] If the execution context 114 includes quantum computation threat classification information and the quantum computation threat classification information satisfies predetermined conditions, the authenticity processing candidate sequence identification unit 83 may identify an authenticity processing candidate sequence that includes a signature verification processing candidate using a quantum computation-resistant cryptographic scheme, as shown in Figure 16.
[0132] If the execution context 114 includes quantum key distribution session establishment information or corresponding session identification information, the authenticity processing candidate sequence identification unit 83 may identify an authenticity processing candidate sequence that includes an evidence acquisition processing candidate for acquiring authentication information based on key materials shared by the quantum key distribution session, or a reference generation processing candidate for generating reference information corresponding to the quantum key distribution session, as shown in Figure 17.
[0133] If the execution context 114 includes quantum computation threat classification information or cryptographic scheme transition condition information as threat information originating from quantum computers, and an update to this information is detected, the authenticity processing candidate sequence identification unit 83 may regenerate new authenticity execution procedure data 115 based on the updated execution context 114, as shown in Figure 18.
[0134] Furthermore, based on the updated asset relationship information, parent asset information, or child asset information contained in the execution context 114, the authenticity processing candidate column identification unit 83 may regenerate the authenticity execution procedure data 115 corresponding to the updated asset relationship. Figure 15 is a flowchart showing an example of the regeneration of the authenticity execution procedure data 115 and the recording of the reconstruction history 118 in response to the update of the asset relationship.
[0135] If a sequence of authenticity processing candidates that can be connected from the identification acquisition stage to the result recording stage cannot be constructed, the execution control unit 84 sets the authenticity determination to a non-execution state, as shown in Figure 19, and generates non-execution state data 117 indicating that non-execution state, and records it in the audit record 116.
[0136] Furthermore, if, in the execution context 114, an attempt is made to obtain quantum computation threat classification information or quantum key distribution (QKD) session information, but necessary elements are missing due to communication failures, timeouts, or hardware incompatibility on terminal 2, fallback processing may be defined. For example, if a QKD session is not established, the processor 80 may not immediately determine that it is in a non-executable state, but rather dynamically relax the application condition information and reconstruct and execute an "alternative authenticity processing candidate list" that incorporates evidence acquisition processing candidates using standard public-key cryptography schemes such as Diffie-Hellman key exchange, or existing high-strength symmetric-key cryptography schemes as alternative candidates. In this case, a warning that it is not the highest security classification and a record that standard encryption was used will be added to the audit record 116.
[0137] As shown in Figure 12, the audit record unit 85 generates an audit record 116 by associating the identification information of the authenticity execution procedure data 115 with the results of the authenticity determination. If necessary, the audit record 116 may also record, in association with at least a portion of the candidate identifier column, the requested expert risk classification information, the identification elements, evidence elements or reference information used in the authenticity determination, the non-execution status data 117, and the reconstruction history 118 included in the authenticity execution procedure data 115.
[0138] The identification elements are information for identifying the asset being appraised 5, its constituent assets, related records, references, or correspondences, and may include at least one of the following: product identifier, transaction hash, QR code, contract address, and token ID.
[0139] Product identifiers are identification information for identifying tangible assets or composite assets containing such assets, and may include manufacturing numbers, part numbers, lot numbers, serial numbers, or similar identifiers.
[0140] A transaction hash is identification information corresponding to a transaction, registration, or state change recorded on a distributed ledger or other record-keeping location, and a two-dimensional code may represent the above identification information as an optically readable code. A contract address and token ID may function as identification information for uniquely identifying a smart contract or token.
[0141] Evidence elements are information used to prove or authenticate authenticity, ownership, possession, qualification, provenance, signature validity, or other aspects, and may include at least one of the following: wallet information, decentralized identifiers, verifiable credentials, signature data, external record references, and guarantee information.
[0142] Wallet information may be information about a cryptocurrency wallet, a token holder, or an associated address. Decentralized identifiers may be identifiers that decentralize the identification of a subject or object. Verifiable credentials may be information that expresses qualifications, attributes, or authority in a verifiable format.
[0143] Signature data may be a signature generated by a private key or a corresponding signing means. External record references may be references to information recorded in an external database, distributed file server, distributed ledger, or other record location. Guarantee information may be information relating to product warranty, authorized distribution warranty, or authenticity warranty.
[0144] Authentication elements are selected from at least some of the identification and evidence elements and are used in multi-signature authentication. Authentication elements may include, for example, at least one of the following: product identifier, QR code, wallet information, verifiable credentials, signature data, or information to which third-party authentication has been granted.
[0145] When using multi-signature authentication, authenticity determination may be based on the alignment or correspondence of at least two of the multiple authentication factors. Furthermore, at least one of the above multiple authentication factors may be an authentication factor that has been certified by a third party.
[0146] The recording destination is a place where information related to the appraised asset 5 or the determination of authenticity is recorded, stored, or referenced, and may include external databases 8a, distributed file servers 8b, distributed ledgers 8c, and other information storage locations.
[0147] The external database 8a may hold the asset to be appraised 5, component assets, authenticity determination history, authentication information, or related metadata. The distributed file server 8b may hold evidence data, reference data, or authentication data. The distributed ledger 8c may record identification information, reference information, token reference information, certification results, or other information requiring traceability.
[0148] The appraisal certification system 1 can construct a sequence of authenticity processing candidates suitable for the asset 5 being appraised, based on the combination of the above-mentioned identification element, evidence element, and recording destination. For example, if only the identification element is available, a sequence of authenticity processing candidates starting from an identification acquisition processing candidate based on that identification element may be identified.
[0149] Furthermore, if evidence elements relating to signature data, verifiable credentials, or zero-knowledge proofs are available, candidate verification or authentication processes corresponding to such evidence elements may be included in the authenticity process candidate column. In addition, if distributed ledger 8c or other record destinations are available, candidate reference generation or matching processes corresponding to such record destinations may be included in the authenticity process candidate column.
[0150] Thus, the appraisal and certification system 1 can flexibly configure a list of candidate sequences for authenticity processing depending on the combination of identification elements, evidence elements, and recording destinations.
[0151] Furthermore, if the asset subject to appraisal 5 is a composite asset, the above-mentioned identification elements, evidence elements, and record destinations may correspond to the entire composite asset, or they may correspond individually to each component asset.
[0152] Furthermore, if quantum computation threat classification information or quantum key distribution session information is available, in addition to the above identification element, the above evidence element, and the above recording destination, candidate signature verification processing using quantum computation-resistant cryptography or candidate evidence acquisition processing or reference generation processing based on quantum key distribution sessions may be included in the authenticity processing candidate column.
[0153] As described above, in this embodiment, by appropriately combining identification elements, evidence elements, and recording destinations, it is possible to construct a candidate sequence of authenticity processing suitable for determining authenticity for a wide range of assets 5 subject to appraisal, including tangible assets, intangible assets, and composite assets.
[0154] Furthermore, the appraisal certification system 1 can achieve appropriate authenticity determination according to the nature of the appraisal request, the asset type, and the available information by executing only the authenticity processing candidates that are set to an executable state from the above list of authenticity processing candidates.
[0155] The appraisal request risk classification calculation unit 82 acquires input information related to the appraisal request and calculates appraisal request risk classification information using an artificial intelligence (AI) model based on said input information.
[0156] The input information for the above appraisal request may include the source of the appraisal request identification, the frequency of appraisal requests, past authenticity determination history information, non-execution status data included in past audit records, asset type information of the asset subject to appraisal 5, and other information.
[0157] The artificial intelligence (AI) model may, for example, evaluate whether the risk of misuse, impersonation, unauthorized access, or information leakage is higher compared to a normal appraisal request, and classify the appraisal request into one of several categories. These categories may include, for example, high-risk, medium-risk, and low-risk categories.
[0158] More specifically, as artificial intelligence (AI) models, logistic regression, support vector machines (SVM), random forests, or deep neural networks (DNN) and anomaly detection algorithms (such as Isolation Forest) can be used. In the learning phase, past normal appraisal request logs (requesting IP address, wallet address, request frequency, time of day, identifier of target asset, etc.) are trained as unsupervised or supervised data. The appraisal request risk classification calculation unit 82 extracts feature vectors (e.g., degree of sudden increase in request frequency, similarity to past fraud history, degree of deviation between the geographical location of the requesting IP and the past activity area of the wallet, etc.) from the input information related to the current appraisal request and inputs them into the trained AI model to output the probability (score) of fraudulent use or impersonation. If the score is above a predetermined first threshold (e.g., 80%), it is classified as a high-risk category; if it is below the first threshold but above the second threshold (e.g., 30%), it is classified as a medium-risk category; and if it is below the second threshold, it is classified as a low-risk category.
[0159] The appraisal request risk classification calculation unit 82 may extract at least one of the following as features from the input information relating to the current appraisal request: the amount of change in the frequency of appraisal requests, the similarity with past non-execution status data, the similarity with negative results in past authenticity judgment history, the degree of deviation between past request trends relating to the appraisal request source identification information and past activity trends relating to wallet information or decentralized identifiers, and the degree of unnaturalness of the request pattern according to the asset type information of the asset to be appraised 5.
[0160] For example, if a large number of authentication requests are sent in a short period of time from the same or related authentication request source, if a new authentication request is sent from an authentication request source that has previously recorded non-execution status data, or if there is a significant discrepancy between past request trends related to authentication request source identification information and past activity trends related to wallet information or decentralized identifiers, an artificial intelligence (AI) model may be trained to treat these as highly likely to be instances of misuse, impersonation, or unauthorized access.
[0161] Furthermore, if the asset to be appraised 5 is a composite asset, and some of the parent asset information, child asset information, physical identification information, digital image information corresponding to the physical asset (digital twin information), or token reference information corresponding to the real-world asset is missing or shows a different correspondence from the past authenticity determination history, the artificial intelligence (AI) model may be trained to treat it as having a high risk due to inconsistencies in asset relationships.
[0162] Thus, since the frequency of appraisal requests, past non-execution status data, past authenticity determination history, appraisal requester identification information, wallet information, decentralized identifiers, and asset type information can correlate with the likelihood of misuse, impersonation, unauthorized access, information leakage, or inconsistencies in asset relationships, an artificial intelligence (AI) model can calculate appraisal request risk classification information based on this input information.
[0163] In the inference phase, the appraisal request risk classification calculation unit 82 may input features extracted from the input information relating to the current appraisal request into the trained artificial intelligence (AI) model to output a score indicating the possibility of misuse, impersonation, unauthorized access, information leakage, or inconsistency in asset relationships.
[0164] If the score is above a predetermined first threshold, it may be classified as a high-risk category; if it is below the first threshold but above a predetermined second threshold, it may be classified as a medium-risk category; and if it is below the second threshold, it may be classified as a low-risk category.
[0165] The appraisal request risk classification calculation unit 82 outputs the appraisal request risk classification information calculated by the artificial intelligence (AI) model to the authenticity processing candidate column identification unit 83.
[0166] The authenticity processing candidate sequence identification unit 83 may switch the authenticity processing candidate sequence to be executed based on the above-mentioned appraisal request risk classification information. For example, if a high-risk classification is indicated, the authenticity processing candidate sequence that includes an authenticity processing candidate that suppresses the direct exposure of confidential information may be identified instead of the direct evidence acquisition processing candidate.
[0167] Furthermore, when indicating a low-risk or normal category, a standard authenticity processing candidate sequence using available identification and evidence elements may be identified.
[0168] Furthermore, if the asset to be appraised 5 is a composite asset, the appraisal request risk classification calculation unit 82 may calculate appraisal request risk classification information based on the asset type information, taking into account the relationships or reference relationships of each component asset that constitutes the composite asset.
[0169] The appraisal request risk classification calculation unit 82 may associate the appraisal request risk classification information with the result of the authenticity determination or the result information included in the audit record, store it as training data, and use it to update the artificial intelligence (AI) model.
[0170] As a result, the appraisal request risk classification calculation unit 82 can calculate classification information that helps in selecting a more appropriate authenticity processing candidate column, according to the asset to be appraised 5, the source of the appraisal request, past judgment history, asset type, and other information.
[0171] Figure 13 is a flowchart illustrating an example of identifying a column of authenticity processing candidates, including candidates for zero-knowledge proof acquisition and zero-knowledge proof verification, based on the risk classification information of the appraisal request.
[0172] The authenticity processing candidate table 111 may record candidates for zero-knowledge proof acquisition processing and candidates for zero-knowledge proof verification processing. The authenticity processing candidate column identification unit 83 may include these authenticity processing candidates in the authenticity processing candidate column when the appraisal request risk classification information indicates a high-risk classification.
[0173] A candidate for zero-knowledge certification is a candidate for obtaining zero-knowledge certification that demonstrates the existence of at least one of the prescribed qualifications, authority, or possessed facts without disclosing the confidential information itself.
[0174] The above-mentioned qualifications, authority, or possessed facts may include, for example, owner status, possessor status, wallet ownership status, validity of verifiable credentials, possession of signing keys, and other information.
[0175] The authenticity processing candidate column identification unit 83 may include zero-knowledge proof acquisition processing candidates in the authenticity processing candidate column instead of evidence acquisition processing candidates that directly acquire wallet information, verifiable credentials, or signature data.
[0176] A candidate zero-knowledge proof verification process is a candidate process for obtaining the result information of the acquired zero-knowledge proof and passing that result information as evidence to the verification stage.
[0177] In other words, in determining authenticity, it is possible to use information indicating whether or not a zero-knowledge proof is valid, without disclosing the zero-knowledge proof itself.
[0178] Even when a zero-knowledge proof is used, the audit record section 85 may not include the zero-knowledge proof itself in the audit record 116, but may record the type of proof, proof identification information, established result information, and verification time information.
[0179] This allows the authentication and certification system 1 to obtain the authentication results necessary for determining authenticity while preventing excessive exposure of confidential or highly confidential information.
[0180] Furthermore, when multiple authentication factors are used, the zero-knowledge proof acquisition process candidate may be used to prove the validity of at least some of the multiple authentication factors, either individually or in combination.
[0181] Furthermore, if at least one authentication element is an authentication element that has been granted third-party certification, the zero-knowledge proof acquisition process candidate may include proof of the establishment or validity of said third-party certification.
[0182] In the example shown in Figure 13, it is first determined whether or not the case falls into the high-risk category, and if it does, a sequence of authenticity processing candidates, including candidates for zero-knowledge proof acquisition processing and zero-knowledge proof verification processing, is identified.
[0183] In this way, by selectively incorporating zero-knowledge proof acquisition processing candidates and zero-knowledge proof verification processing candidates according to the risk classification information of the appraisal request, it is possible to achieve both confidentiality and accuracy in determining authenticity according to the degree of risk of the appraisal request.
[0184] Therefore, according to the zero-knowledge proof embodiment, authenticity determination can be performed for high-risk appraisal requests while suppressing the exposure of evidentiary elements.
[0185] The above-mentioned asset 5 may be a tangible asset, an intangible asset, or a composite asset. A composite asset is an asset that includes or references two or more component assets, and these component assets may be tangible assets, intangible assets, or other composite assets.
[0186] Therefore, a composite asset is not limited to an asset that combines a tangible asset and an intangible asset, but may also include combinations of tangible assets, combinations of intangible assets, or combinations of composite assets themselves.
[0187] For example, the asset to be appraised 5 may be a composite asset including a tangible part and intangible design data, a composite asset including a tangible product and tangible accessories, or a composite asset including intangible license information and intangible usage history data.
[0188] In a composite asset, digital image information corresponding to a physical asset, i.e., digital twin information, may be maintained. This digital twin information may represent the state, attributes, history, or composition of the physical object.
[0189] Furthermore, the execution context 114 may include token reference information corresponding to real-world assets. The above token reference information may be a reference to a token or related record corresponding to the asset being appraised 5 or its constituent assets.
[0190] The authenticity processing candidate column identification unit 83 may include authenticity processing candidates in the authenticity processing candidate column if the asset 5 to be appraised is a composite asset and the digital twin information and the token reference information are available.
[0191] The above-mentioned physical identification information may include product identifiers, serial numbers, part numbers, lot numbers, and other identification information corresponding to tangible assets.
[0192] The above digital twin information may include information such as the configuration, state, history, inspection results, update history, and other information of the physical object.
[0193] The above token reference information may include a token ID, contract address, transaction hash, and other information for referencing tokens or related records corresponding to real-world assets.
[0194] The authenticity processing candidate sequence identification unit 83 can determine the authenticity of the entire composite asset by checking the correspondence, consistency, or presence or absence of contradictions between the physical identification information, the digital twin information, and the token reference information.
[0195] Furthermore, individual identification elements, evidence elements, or recording destinations may be associated with each component asset that makes up the composite asset. In this case, the authenticity processing candidate sequence identification unit 83 may sequentially connect authenticity processing candidates for multiple component assets to form an authenticity processing candidate sequence for the entire composite asset.
[0196] This section describes specific examples (use cases) of composite assets and consistency verification in this embodiment. (Example 1: Distribution management of luxury brand goods and works of art) If the asset to be appraised 5 is a luxury wristwatch (compound asset), three pieces of information are obtained: the serial number (physical identification information) read from the NFC chip embedded in the watch body, which is a tangible asset; the "repair history and condition (digital twin information)" of the watch held in the memory unit 110; and the NFT token ID (token reference information) representing ownership minted on the distributed ledger 8c. In the verification stage, the hash value derived from the physical identification information is checked to see if it matches the value recorded in the metadata within the digital twin information, and whether the latest updated transaction hash of the digital twin information matches the reference recorded in the smart contract of the NFT. This checks whether the item has been replaced with a physical counterfeit or whether there is a discrepancy between digital ownership and the actual item. (Example 2: Parts replacement and traceability for industrial machinery) If the asset to be appraised 5 is a composite asset consisting of a parent asset (manufacturing plant machine body) and a child asset (critical replacement part), the unique marking code (physical identification information) of the child asset is linked to the "operating time and non-destructive testing data (digital twin information)" of that part and the verifiable credentials (token reference information or evidence element) issued by the legitimate manufacturer of the part. When a part replacement (update of asset relationship) occurs, the execution context acquisition unit 81 detects these and updates the topology (configuration relationship) of the digital twins of the parent and child assets, while dynamically verifying the consistency of whether the replaced part is genuine and meets the required safety standards.
[0197] Asset 5 being appraised and other assets subject to integration, separation, exchange, addition, or reference to Asset 5 being appraised may each be a tangible asset, an intangible asset, or a composite asset. Therefore, the combination of Asset 1 and Asset 2 may include at least the following combinations: tangible asset, tangible asset, tangible asset, intangible asset, tangible asset, composite asset, intangible asset, tangible asset, intangible asset, intangible asset, intangible asset, composite asset, composite asset, tangible asset, composite asset, intangible asset, composite asset, composite asset.
[0198] If such an update to an asset relationship is detected, the authenticity processing candidate column identification unit 83 may regenerate the authenticity execution procedure data 115 based on the updated execution context 114.
[0199] The regenerated authenticity execution procedure data 115 may include a different candidate identifier sequence, execution order, or usage elements than the authenticity execution procedure data 115 before the update, and the audit record unit 85 may record the identification information of the authenticity execution procedure data 115 before and after the update as a reconstruction history 118.
[0200] Figure 14 is a flowchart illustrating an example of a process for verifying the consistency between digital mapping information corresponding to physical assets and token reference information corresponding to real-world assets for a composite asset.
[0201] Figure 15 is a flowchart showing an example of a process that regenerates authenticity execution procedure data 115 and records reconstruction history 118 in response to updates to asset relationships.
[0202] In this way, by using token reference information corresponding to composite assets, digital twin information, and real-world assets, authenticity determination can be performed on a broader asset structure than when the asset being appraised 5 is a single asset.
[0203] Therefore, according to the composite asset, digital twin, and real-world asset corresponding token embodiments, it is possible to determine authenticity for a wide range of assets subject to appraisal 5, including tangible assets, intangible assets, and composite assets, taking into account their constituent relationships and corresponding relationships.
[0204] The execution context described above may further include at least one of the following: asset relationship update information, parent asset information, and child asset information. The asset relationship update information may include information indicating changes in asset relationships such as integration, separation, exchange, addition, reference, etc.
[0205] The asset being appraised 5 and the other assets subject to integration, separation, exchange, addition, or reference to said asset being appraised 5 may each be a tangible asset, an intangible asset, or a composite asset. Therefore, the combination of parent and child assets, or pre-renewal and post-renewal assets, may include any combination of these three types.
[0206] The authenticity processing candidate column identification unit 83 may generate the updated execution context 114 based on the updated asset relationship information, the parent asset information, and the child asset information, and re-identify the authenticity processing candidate column based on the updated execution context 114.
[0207] The authenticity processing candidate column identification unit 83 regenerates the updated authenticity execution procedure data 115 based on the updated authenticity processing candidate column. At this time, the candidate identifier column, execution order, or usage elements included in the authenticity execution procedure data 115 before the update may match the candidate identifier column, execution order, or usage elements included in the updated authenticity execution procedure data 115, or they may be partially or entirely different.
[0208] The audit record unit 85 may generate a reconstruction history 118 by associating the identification information of the authenticity execution procedure data 115 before the update with the identification information of the authenticity execution procedure data 115 after the update. The reconstruction history 118 may include at least a portion of the update information of the asset relationship, the parent asset information, the child asset information, the update time information, or the update reason information.
[0209] This allows the appraisal and certification system 1 to reconstruct a sequence of authenticity processing candidates that conforms to the updated constituent relationships, even if changes occur in the asset relationships.
[0210] For example, if an asset that is a tangible part of a composite asset is exchanged, the authenticity processing candidate sequence may be switched to one that assumes the identification and evidence elements corresponding to the component asset after the exchange.
[0211] Furthermore, if an intangible asset is added or a reference relationship is updated, the authenticity processing candidate column may be switched to include identification elements, evidence elements, or reference information related to the intangible asset.
[0212] Furthermore, if the parent-child relationship of a composite asset changes, the authenticity execution procedure data 115 reflecting the correspondence between the parent and child assets may be regenerated, making it possible to track the procedures before and after the update.
[0213] Figure 15 is a flowchart showing an example of a process that regenerates authenticity execution procedure data 115 and records reconstruction history 118 in response to updates to asset relationships.
[0214] The authenticity processing candidate table 111 may further include signature verification processing candidates using quantum computation-resistant cryptography (PQC). The above-mentioned signature verification processing candidates using quantum computation-resistant cryptography (PQC) are processing candidates for verifying signature data generated by a signature scheme that is resistant to threats originating from quantum computers.
[0215] The execution context 114 may further include quantum computing threat classification information. This quantum computing threat classification information may be information indicating the degree of threat caused by quantum computers, the need for cryptographic scheme migration, or the level of security.
[0216] The authenticity processing candidate sequence identification unit 83 may identify an authenticity processing candidate sequence that includes a signature verification processing candidate using a quantum computation-resistant cryptography scheme (PQC) if the quantum computation threat classification information satisfies predetermined conditions.
[0217] The candidate signature verification process using the above-mentioned quantum computation-resistant cryptography (PQC) may obtain the public key information, signature data, or related verification parameters corresponding to the quantum computation-resistant cryptography, and pass the signature verification result as evidence to the above-mentioned verification stage.
[0218] Furthermore, if the quantum computation threat classification information indicates a higher classification, the authenticity processing candidate sequence identification unit 83 may identify an authenticity processing candidate sequence that includes a signature verification processing candidate using the quantum computation-resistant cryptography (PQC) in place of, or in addition to, the conventional signature verification processing candidate.
[0219] If a candidate signature verification process using the above-mentioned quantum computation-resistant cryptography (PQC) is used, the audit record unit 85 may record at least a portion of the identification information of the candidate process, the cryptographic scheme used, the signature verification result, or related reference information in the audit record 116.
[0220] As a result, the authentication and certification system 1 can perform authenticity determination using quantum-resistant cryptography (PQC) even when threats originating from quantum computers are anticipated.
[0221] Figure 16 is a flowchart illustrating an example of a process for identifying a sequence of authenticity processing candidates, including signature verification processing candidates using quantum computation-resistant cryptography (PQC).
[0222] Therefore, according to the quantum computation-resistant cryptography embodiment, the cryptographic processing candidate used for authenticity determination can be appropriately switched according to the quantum computation threat classification information.
[0223] The authenticity processing candidate table 111 may further include evidence acquisition processing candidates that acquire authentication information based on key material shared by a quantum key distribution session, or reference generation processing candidates that generate reference information corresponding to the quantum key distribution session.
[0224] The execution context 114 may further include at least one of the following: quantum key distribution session establishment information or corresponding session identification information. The quantum key distribution session establishment information is information indicating that a quantum key distribution session has been established, and the session identification information may be information for identifying the quantum key distribution session.
[0225] The authenticity processing candidate sequence identification unit 83 may identify an authenticity processing candidate sequence that includes the evidence acquisition processing candidate or the reference generation processing candidate based on the quantum key distribution session establishment information or the session identification information.
[0226] The above evidence acquisition process candidate may acquire authentication information 128 generated based on key material shared by the quantum key distribution session, and pass on said authentication information 128 as evidence element to the above verification stage.
[0227] The above-mentioned reference generation process candidate may generate reference information corresponding to the quantum key distribution session based on the quantum key distribution session establishment information or session identification information, and pass the said reference information to the recording destination or another authenticity process candidate.
[0228] Furthermore, the authenticity processing candidate sequence identification unit 83 may include processing candidates based on quantum key distribution sessions in the same authenticity processing candidate sequence as signature verification processing candidates using quantum computation-resistant cryptography (PQC), or it may select them as separate authenticity processing candidate sequences.
[0229] If a processing candidate based on a quantum key distribution session is used, the audit record unit 85 may record the session establishment information, session identification information, acquired authentication information, generated reference information, or at least a part thereof, in association with the audit record 116.
[0230] Figure 17 is a flowchart illustrating an example of a process for identifying a sequence of authenticity processing candidates, including candidates for evidence acquisition or reference generation based on a quantum key distribution session.
[0231] Therefore, according to the quantum key distribution session embodiment, authentication information or reference information necessary for authenticity determination can be appropriately incorporated by utilizing the key material or corresponding information shared by the quantum key distribution session.
[0232] The execution context 114 may further include at least one of the following as threat information originating from a quantum computer: quantum computation threat classification information or cryptographic scheme transition condition information.
[0233] The above quantum computing threat classification information may indicate the progress in the computing power of quantum computers, the increased risk of decryption against existing cryptographic schemes, the increased likelihood of attacks against cryptocurrency-related systems, or the degree of necessity for migrating to quantum-resistant cryptographic schemes.
[0234] The above encryption method transition condition information may be information indicating at least one of the following: reaching a predetermined threat level, reaching a predetermined time, receiving a predetermined external notification, updating policy information at a predetermined recording location, or making a predetermined administrator input.
[0235] If the authenticity processing candidate sequence identification unit 83 detects an update to the quantum computation threat classification information or the cryptographic scheme transition condition information, it may identify a new authenticity processing candidate sequence based on the updated execution context 114.
[0236] The authenticity processing candidate sequence identification unit 83 may regenerate new authenticity execution procedure data 115 based on the new authenticity processing candidate sequence.
[0237] During the above regeneration, the authenticity processing candidate column identification unit 83 may retain the authenticity processing candidates that were included in the authenticity processing candidate column before the update, delete some of them, or add new authenticity processing candidates.
[0238] For example, if the quantum computation threat classification information indicates a predetermined high threat classification, the authenticity processing candidate sequence identification unit 83 may newly identify an authenticity processing candidate sequence that includes a signature verification processing candidate using a quantum computation-resistant cryptographic scheme, and use it in place of the conventional authenticity processing candidate sequence that consists only of signature verification processing candidates.
[0239] Furthermore, if a candidate for evidence acquisition processing or a candidate for reference generation processing based on a quantum key distribution session is available, the authenticity processing candidate sequence identification unit 83 may add such candidate to a new authenticity processing candidate sequence.
[0240] The audit record unit 85 may associate the identification information of the authenticity execution procedure data 115 before the update with the identification information of the authenticity execution procedure data 115 after the update and record it in the audit record 116.
[0241] The audit record 116 above may further record, in association with at least a portion of the quantum computation threat classification information or cryptographic scheme transition condition information that caused the above update, the update time information, the authenticity processing candidate column before the update, the authenticity processing candidate column after the update, and the update reason information.
[0242] This allows the authentication and certification system 1 to flexibly update the sequence of candidate processes used for authenticity determination, depending on the degree of threat posed by quantum computers or the need for a change in cryptographic methods.
[0243] Furthermore, by associating the identification information of the authenticity execution procedure data 115 before and after the update, it is possible to track and maintain a history of procedure changes in response to quantum computer threats.
[0244] Figure 18 is a flowchart showing an example of the process of regenerating authenticity execution procedure data 115 in response to updates to threat information or cryptographic scheme transition condition information caused by quantum computers.
[0245] Therefore, according to the quantum computer threat update embodiment, the authenticity determination process can be adaptively reconfigured in response to changes in threats originating from quantum computers, and the change history can be maintained in an auditable manner.
[0246] If the authenticity processing candidate column identification unit 83 cannot configure an authenticity processing candidate column that can be connected from the identification acquisition stage to the result recording stage based on the execution context 114, the appraisal request risk classification information, the authenticity processing candidate table 111, and the candidate processing connection relationship table 112, it may set the authenticity determination to a non-executable state.
[0247] The above non-execution state may be set when there are insufficient identification elements, insufficient evidence elements, a predetermined recording destination is unavailable, a connectable authenticity processing candidate column cannot be formed in the candidate processing connection relationship table 112, or an authenticity processing candidate required according to the appraisal request risk classification information is unavailable.
[0248] For example, if a high-risk category cannot be represented, but a sequence of authenticity processing candidates including zero-knowledge proof acquisition processing candidates and zero-knowledge proof verification processing candidates cannot be constructed, the authenticity determination may be set to a non-executable state.
[0249] Furthermore, in authenticity determination of a composite asset, if any of the physical identification information, digital twin information, or token reference information is missing, and it is not possible to construct a candidate sequence for authenticity processing to verify consistency, the authenticity determination may be set to a non-executable state.
[0250] Furthermore, if the quantum computation threat classification information satisfies predetermined conditions, and it is not possible to construct a sequence of authenticity processing candidates that includes a signature verification processing candidate using a quantum computation-resistant cryptography scheme or a processing candidate based on a quantum key distribution session, the authenticity determination may be set to a non-executable state.
[0251] The execution control unit 84 may, as a setting to a non-execution state, not only set the state of the execution control table 113 corresponding to the authenticity processing candidate not included in the authenticity processing candidate column to a non-execution state, but may also perform at least one of the following: invalidating API call permission information, invalidating the execution flag, blocking container startup permission information, or rewriting function call destination control information.
[0252] This prevents authenticity processing candidates that have been determined to be unselected or unexecutable from actually being invoked.
[0253] If the authenticity determination is set to a non-execution state, the audit record unit 85 may generate non-execution state data 117 indicating that non-execution state and record it in association with the audit record 116.
[0254] The above non-execution status data 117 may include at least a portion of the non-execution reason information, non-execution time information, identification information of the authenticity processing candidate column that entered the non-execution state, the type of missing element, or information on unmet requirements.
[0255] The audit record unit 85 may record the non-execution status data 117 in association with at least a portion of the appraisal request risk classification information, identification elements, evidence elements, recording destination, or asset type information.
[0256] This allows subsequent appraisal requests to utilize past non-execution status data 117 as part of the input information for the appraisal request, thereby improving the accuracy of the artificial intelligence (AI) model in calculating appraisal request risk classification information.
[0257] Furthermore, by retaining the non-execution status data 117 in the audit record 116, it becomes possible to later verify why an authenticity determination was not performed for the appraisal request in question.
[0258] Figure 19 is a flowchart showing an example of a non-execution state setting process when a candidate sequence for authenticity processing cannot be constructed.
[0259] Therefore, according to the non-execution state embodiment, when it is not possible to construct a candidate sequence of authenticity processing necessary for authenticity determination, it is possible to prevent the execution of unnecessary or incomplete processing and to retain the reason for this in an auditable manner.
[0260] Each functional unit constituting the appraisal and certification system 1 may be realized by the processor 80 executing a program stored in the memory unit 110. That is, the functions of the execution context acquisition unit 81, the appraisal request risk classification calculation unit 82, the authenticity processing candidate sequence identification unit 83, the execution control unit 84, and the audit record unit 85 may be realized by a program.
[0261] The above program may cause the computer to execute a process to obtain an execution context 114 that includes identification elements, evidence elements, recording destination, asset type information, and input information related to the appraisal request for the asset 5 to be appraised.
[0262] Furthermore, the above program may cause the computer to perform a process of calculating appraisal request risk classification information using an artificial intelligence (AI) model based on the input information regarding the appraisal request.
[0263] Furthermore, the program may cause the computer to perform a process to identify authenticity processing candidate columns that include authenticity processing candidates belonging to at least the identification acquisition stage, evidence acquisition stage, verification stage, and result recording stage, and that satisfy the application condition information, based on the authenticity processing candidate table 111, the candidate processing connection relationship table 112, the execution control table 113, the execution context 114, and the appraisal request risk classification information.
[0264] Furthermore, the program may cause the computer to execute a process to generate authenticity execution procedure data 115 that shows the authenticity processing candidate column. The authenticity execution procedure data 115 may include at least a candidate identifier column, execution order, and identification information.
[0265] Furthermore, the program may cause the computer to perform a process that sets the state of the execution control table 113 corresponding to the authenticity processing candidate included in the authenticity execution procedure data 115 to an executable state, and sets the state of the execution control table 113 corresponding to the authenticity processing candidate not included in the authenticity execution procedure data 115 to a non-executable state.
[0266] Furthermore, the program may cause the computer to execute a process of performing an authenticity determination by executing only the authenticity processing candidates set to the executable state according to the authenticity execution procedure data 115.
[0267] Furthermore, the program may cause the computer to execute a process of associating the identification information of the authenticity execution procedure data 115 with the result of the authenticity determination and recording it as an audit record 116.
[0268] When the authentication request risk classification information indicating a high-risk classification is calculated, the program may further cause the computer to execute a process of specifying an authenticity processing candidate sequence including a zero-knowledge proof acquisition processing candidate and a zero-knowledge proof verification processing candidate.
[0269] When the program indicates that the appraisal target asset 5 is a composite asset in the asset form information and the execution context 114 includes token reference information corresponding to digital twin information and real-world assets, the program may further cause the computer to execute a process of specifying an authenticity processing candidate sequence including an authenticity processing candidate for verifying the consistency of the physical-side identification information, the digital twin information, and the token reference information.
[0270] When the quantum computing threat classification information satisfies a predetermined condition, the program may further cause the computer to execute a process of specifying an authenticity processing candidate sequence including a signature verification processing candidate using a quantum computing-resistant encryption method. Also, when quantum key distribution session establishment information or corresponding session identification information is available, the program may further cause the computer to execute a process of specifying an authenticity processing candidate sequence including a proof acquisition processing candidate or a reference generation processing candidate based on the quantum key distribution session.
[0271] When the program detects an update of the quantum computing threat classification information or the encryption method migration condition information as threat information caused by a quantum computer, the program may further cause the computer to regenerate new authenticity execution procedure data 115 based on the updated execution context 114, and associate the identification information of the authenticity execution procedure data 115 before and after the update and record it in the audit record 116.
[0272] Further, when the program cannot construct a sequence of authenticity processing candidates that can be connected from the identification acquisition stage to the result recording stage, the authenticity determination may be set to a non-execution state, and the program may further execute a process of recording non-execution state data 117 indicating the non-execution state in the audit record 116.
[0273] Thus, according to the above program, it is possible to realize an auditable authenticity determination process while dynamically switching a sequence of processing candidates required for authenticity determination according to the asset form of the asset 5 to be appraised, the risk level of the appraisal request, available identification elements, evidence elements, and recording destinations.
[0274] Next, an embodiment of an authentication and certification method will be described. The authentication and certification method according to this embodiment is a method executed by a computer and includes a series of steps for performing an authenticity determination.
[0275] First, in the execution context acquisition step, an execution context 114 including identification elements, evidence elements, recording destinations, asset form information regarding the asset 5 to be appraised, and input information regarding the appraisal request is acquired.
[0276] Next, in the appraisal request risk classification calculation step, appraisal request risk classification information is calculated by an artificial intelligence (AI) model based on the input information regarding the appraisal request.
[0277] Next, in the authenticity processing candidate sequence identification step, based on the authenticity processing candidate table 111, the candidate processing connection relationship table 112, the execution context 114, and the appraisal request risk classification information, an authenticity processing candidate sequence including authenticity processing candidates belonging to at least the identification acquisition stage, the evidence acquisition stage, the verification stage, and the result recording stage and satisfying the application condition information is identified.
[0278] Next, in the authenticity execution procedure data generation step, authenticity execution procedure data 115 indicating the authenticity processing candidate sequence is generated.
[0279] Next, in the state setting step, the state of the execution control table 113 corresponding to the authenticity processing candidate included in the authenticity execution procedure data 115 is set to the executable state, and the state of the execution control table 113 corresponding to the authenticity processing candidate not included in the authenticity execution procedure data 115 is set to the non-executable state.
[0280] Next, in the authenticity determination process, only the authenticity processing candidates set to the executable state described above are executed according to the authenticity execution procedure data 115 described above, and the authenticity of the asset 5 to be appraised is determined.
[0281] Next, in the audit recording process, the identification information of the authenticity execution procedure data 115 and the result of the authenticity determination are associated and recorded as audit record 116.
[0282] In the above authentication and certification method, if the authentication request risk classification information indicating a high-risk classification is calculated, instead of the evidence acquisition processing candidate that directly acquires wallet information, verifiable credentials, or signature data, a sequence of authenticity processing candidates including zero-knowledge proof acquisition processing candidates and zero-knowledge proof verification processing candidates may be identified.
[0283] Furthermore, in the above appraisal and certification method, if the asset to be appraised 5 is a composite asset and digital twin information and token reference information corresponding to the real-world asset are available, a sequence of authenticity processing candidates may be identified, which includes authenticity processing candidates that verify the consistency of the physical identification information, the digital twin information, and the token reference information.
[0284] Furthermore, in the above authentication and certification method, if the quantum computation threat classification information satisfies predetermined conditions, a sequence of authenticity processing candidates, including a signature verification processing candidate using a quantum computation-resistant cryptographic scheme, may be identified.
[0285] Furthermore, if quantum key distribution session establishment information or corresponding session identification information is available, a sequence of authenticity processing candidates including evidence acquisition processing candidates or reference generation processing candidates based on the quantum key distribution session may be identified.
[0286] Furthermore, if the quantum computation threat classification information or the cryptographic method transition condition information, which are threat information originating from quantum computers, is updated, the new authenticity execution procedure data 115 may be regenerated based on the updated execution context 114, and the identification information of the authenticity execution procedure data 115 before and after the update may be associated and recorded in the audit record 116.
[0287] Furthermore, if it is not possible to construct a candidate sequence for authenticity processing that can be connected from the identification acquisition stage to the result recording stage, the authenticity determination may be set to a non-executed state, and non-executed state data 117 indicating that non-executed state may be recorded in the audit record 116.
[0288] Thus, according to this embodiment of the appraisal and certification method, the sequence of processing candidates necessary for determining authenticity can be selected step by step according to the asset type of the asset 5 to be appraised, the degree of risk of the appraisal request, the available identification elements, the evidence elements, and the recording destination, while suppressing the selection of non-selected processing candidates, and the determination of authenticity can be performed in an auditable manner.
[0289] The authentication element 119 is selected from at least some of the identification element and the evidence element and is used in the multi-signature authentication 120.
[0290] Authentication element 119 may include product identifier, QR code, transaction hash, contract address, token ID, wallet information, decentralized identifier, verifiable credentials, signature data, external record reference, guarantee information, zero-knowledge proof result information, and other information.
[0291] In determining authenticity, multi-signature authentication 120 may be established based on the alignment or correspondence of at least two of the multiple authentication factors 119.
[0292] The above-mentioned correspondence or matching may include at least one of the following: referring to the same subject asset 5 or the same component asset; corresponding to the same transaction, registration or change of state; belonging to the same entity; or satisfying the prescribed relationship rules.
[0293] For example, for the asset to be appraised 5 that includes tangible assets, a product identifier or a two-dimensional code may be used as the first authentication element 119, and wallet information, signature data, verifiable credentials, or warranty information may be used as the second authentication element 119, and multi-signature authentication 120 may be executed based on the matching or association of these.
[0294] Also, for assets that are intangible, a transaction hash, contract address, token ID, decentralized identifier, signature data, or verifiable credentials may be used as multiple authentication elements 119.
[0295] Furthermore, when the asset to be appraised 5 is a composite asset, the authentication element 119 corresponding to the entire composite asset and the authentication element 119 corresponding to each constituent asset may be used in combination, and multi-signature authentication 120 may be executed based on the matching or association of the multiple authentication elements 119.
[0296] At least one of the multiple authentication elements 119 may be an authentication element 119 to which third-party authentication 121 is granted. The authentication element 119 to which the third-party authentication 121 is granted may include qualification information, signature information, warranty information, or reference information issued, registered, guaranteed, or certified by a third party.
[0297] The authenticity processing candidate sequence specifying unit 83 may change the number, type, or combination of the authentication elements 119 required for multi-signature authentication 120 according to the appraisal request risk classification information. For example, in a high-risk classification, more authentication elements 119 may be required than in a normal classification, or a combination including at least one authentication element 119 to which third-party authentication 121 is granted may be required.
[0298] Also, when the appraisal request risk classification information indicates a high-risk classification, as at least one of the multiple authentication elements 119, the establishment result information obtained by the zero-knowledge proof acquisition processing candidate and the zero-knowledge proof verification processing candidate may be used.
[0299] If multi-signature authentication 120 is performed, the audit record unit 85 may record at least a portion of the identification information of the authentication elements 119 used, the results of the consistency or correspondence between the authentication elements 119, the presence or absence of third-party authentication 121, and the results of the authenticity determination in association with the audit record 116.
[0300] Figure 20 is an explanatory diagram showing an example of an embodiment that includes an authentication element 119 to which multi-signature authentication 120 and third-party authentication 121 are granted based on the authentication element 119.
[0301] Thus, according to the authentication element and the multi-signature authentication embodiment, the reliability of determining the authenticity of the asset 5 being appraised can be improved by using a combination of at least a portion of the identification element and the evidence element in determining authenticity.
[0302] Each of the above embodiments may be modified in various ways without departing from the spirit of the invention. The main modifications are described below.
[0303] As a variation of the asset, the asset subject to appraisal 5 may be a tangible asset, an intangible asset, or a composite asset, and the composite asset may include or refer to two or more component assets, which may be a tangible asset, an intangible asset, or another composite asset.
[0304] Therefore, a composite asset is not limited to a combination of a tangible asset and an intangible asset, but may also include combinations of tangible assets, intangible assets, or composite assets.
[0305] As variations concerning the identification element, evidence element, and authentication element, the type, number, and combination of specific information included in each element may be changed as appropriate. For example, a part of the identification element may be used as an evidence element, and a part of the evidence element may be used as an authentication element.
[0306] As a variation of the artificial intelligence (AI) model, the type of input information used to calculate the risk classification information for appraisal requests, the weighting, the number of classification categories, the threshold, or the learning method may be changed as appropriate.
[0307] As a variation of zero-knowledge proofs, the object of proof, proof format, verification method, and the granularity of the information on the proven result recorded in the audit record may be changed as appropriate.
[0308] As a variation of the token reference information corresponding to composite assets, digital twin information, and real-world assets, the number of layers of constituent assets, the mapping method, the target of consistency verification, and the method of obtaining token reference information may be changed as appropriate.
[0309] As a variation of the quantum computation-resistant cryptography, the signature scheme, public key scheme, key length, verification method, and method of classifying quantum computation threat classification information used may be changed as appropriate.
[0310] As a variation of the quantum key distribution session, the method for generating session establishment information, session identification information, authentication information based on shared key material, or reference information may be modified as appropriate.
[0311] The regeneration conditions, regeneration range, recording items of the reconstruction history 118, and association method with the audit record 116 of the authenticity execution procedure data 115 based on threat information or cryptographic method transition condition information originating from quantum computers may be changed as appropriate.
[0312] The data structures, storage formats, recording destinations, and update methods for the authenticity processing candidate table 111, candidate processing connection relationship table 112, execution control table 113, execution context 114, authenticity execution procedure data 115, audit record 116, non-execution status data 117, and reconstruction history 118 may be changed as appropriate.
[0313] As variations of the program embodiment and the authentication and certification method embodiment, the order of each process, the division unit, the integration unit, the execution entity, and the distributed execution form may be changed as appropriate.
[0314] Although embodiments of the present invention have been described above, the present invention is not limited to the above embodiments and can be implemented with various modifications without departing from the spirit of the invention. [Industrial applicability]
[0315] This invention can be used in various industrial fields that require authenticity determination, provenance management, ownership or qualification verification, certification, audit record generation, and reconstruction history management of tangible assets, intangible assets, and composite assets.
[0316] For example, the present invention can be applied to manufacturing, parts distribution, repair, maintenance, recycling, secondary distribution, logistics, warehousing, authentication services, information processing services, software distribution, digital content provision, rights management, license management, and related industrial fields. Furthermore, the present invention can be applied to systems dealing with composite assets where physical objects and digital image information are associated, assets having token reference information corresponding to real-world assets, assets requiring responses to threats originating from quantum computers, or assets requiring multi-signature authentication based on multiple authentication factors. Therefore, the present invention has broad industrial applicability as a technology for auditably managing authenticity determination processes while switching them according to the situation. [Explanation of Symbols]
[0317] 1. Authentication and Certification System 2 terminals 5. Assets to be appraised 8a External databases 8b Distributed file server 8c distributed ledger 10 Public telecommunications network 80 processors 81 Execution Context Acquisition Unit 82. Risk Classification Calculation Unit for Appraisal Requests 83 Authenticity Processing Candidate Sequence Identification Unit 84 Execution Control Unit 85 Audit Records Department 110 Storage section 111 Authenticity Processing Candidate Table 112 Candidate Processing Connection Relationship Table 113 Execution control table 114 Execution Context 115 Authenticity Execution Procedure Data 116 Audit Records 117 Non-executable status data 118 Reconstruction History 119 Authentication Factors 120 Multi-Signature Authentication 121 Third-party certification 122 Physical identification information 123 Digital Image Information for Physical Assets 124 Token reference information corresponding to real-world assets 125 Quantum Computing Threat Classification Information 126 Quantum Key Distribution Session Establishment Information 127 Session Identification Information 128 Authentication Information 129 Information on the conditions for transitioning to a new encryption method
Claims
1. An appraisal certification system for determining the authenticity of an asset subject to appraisal, The aforementioned assets subject to appraisal are tangible assets, intangible assets, or composite assets. Equipped with a processor and memory, The aforementioned storage unit is For each authenticity processing candidate, an authenticity processing candidate table is used to record the candidate identifier, processing stage, request input type, generated output type, and applicable condition information in association with each candidate. A candidate processing connection relationship table that shows whether a connection is possible between the generated output type of the pre-stage authenticity processing candidate and the requested input type of the post-stage authenticity processing candidate, An execution control table indicating whether each authenticity processing candidate is in an executable or non-executable state, Remember this, The aforementioned processor, An execution context is obtained that includes identification elements, evidence elements, recording destination, asset type information, and input information related to the appraisal request for the aforementioned asset to be appraised. Based on the input information regarding the aforementioned appraisal request, an artificial intelligence (AI) model calculates the appraisal request risk classification information. Based on the execution context, the appraisal request risk classification information, the authenticity processing candidate table, and the candidate processing connection relationship table, an authenticity processing candidate column is identified that includes authenticity processing candidates belonging to at least the identification acquisition stage, the evidence acquisition stage, the verification stage, and the result recording stage, and that satisfy the application condition information indicating the conditions for application to the authenticity determination of the asset subject to appraisal, and authenticity execution procedure data showing the authenticity processing candidate column is generated. The state of the execution control table corresponding to the authenticity processing candidate included in the authenticity execution procedure data is set to an executable state. The state of the execution control table corresponding to the authenticity processing candidate not included in the authenticity execution procedure data is set to a non-execution state. Only the authenticity processing candidates set to the executable state are executed according to the authenticity execution procedure data to perform authenticity determination. The identification information of the authenticity execution procedure data and the result of the authenticity determination are recorded as an audit record in association with each other. A certification system characterized by the following features.
2. The aforementioned composite asset is an asset that includes or references two or more component assets, The aforementioned component assets are tangible assets, intangible assets, or other composite assets. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
3. The identification element included in the execution context includes at least one of the following: product identifier, transaction hash, QR code, contract address, and token ID. The evidence elements included in the execution context include at least one of wallet information, decentralized identifiers, verifiable credentials, signature data, external record references, and guarantee information. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
4. The input information relating to the appraisal request includes at least two of the following: appraisal request source identification information, appraisal request frequency information, past authenticity determination history information, non-execution status data included in past audit records, and asset type information of the asset to be appraised. The artificial intelligence (AI) model calculates the expert opinion request risk classification information that distinguishes whether the authenticity processing candidate column includes a direct evidence acquisition processing candidate or a zero-knowledge proof acquisition processing candidate, based on the input information. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
5. The aforementioned authenticity processing candidate table further includes zero-knowledge proof acquisition processing candidates and zero-knowledge proof verification processing candidates, If the appraisal request risk classification information indicates a high-risk classification, the processor identifies the authenticity processing candidate sequence, which includes the zero-knowledge proof acquisition processing candidate and the zero-knowledge proof verification processing candidate, instead of the evidence acquisition processing candidate that directly acquires wallet information, verifiable credentials, or signature data. The aforementioned zero-knowledge certification acquisition candidate acquires zero-knowledge certification demonstrating the existence of at least one of the prescribed qualifications, authority, or possessed facts without disclosing confidential information. The candidate zero-knowledge proof verification process passes the information indicating the establishment of the zero-knowledge proof as evidence to the verification stage. The aforementioned audit record does not include the zero-knowledge proof itself, but includes the type of proof, proof identification information, proof result information, and verification time information. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
6. The aforementioned asset type information indicates that the asset subject to appraisal is a composite asset, and that the composite asset includes both tangible and intangible assets as constituent assets. If the execution context further includes physical asset-corresponding digital image information (digital twin information) corresponding to the tangible asset and token reference information corresponding to the real-world asset (RWA), The processor identifies the authenticity processing candidate sequence, which includes authenticity processing candidates that verify the integrity of the physical side identification information, the digital twin information, and the token reference information. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
7. The aforementioned asset subject to appraisal and other assets subject to integration, separation, exchange, addition, or reference with respect to said asset subject to appraisal are, respectively, tangible assets, intangible assets, or composite assets. The execution context further includes at least one of the following: asset relationship update information, parent asset information, and child asset information. When the processor detects an update to the execution context, it regenerates the authenticity execution procedure data based on the updated execution context, associates the identification information of the authenticity execution procedure data before and after the regeneration, and records the reconstruction history in the audit record. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
8. The aforementioned authenticity processing candidate table further includes signature verification processing candidates using quantum computation-resistant cryptography (PQC), The execution context further includes quantum computation threat classification information, The processor identifies the authenticity processing candidate sequence, which includes the signature verification processing candidate by the quantum computation-resistant cryptography (PQC), if the quantum computation threat classification information satisfies predetermined conditions. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
9. The authenticity processing candidate table further includes evidence acquisition processing candidates that obtain authentication information based on key material shared by a quantum key distribution (QKD) session, or reference generation processing candidates that generate reference information corresponding to the quantum key distribution (QKD) session, The execution context further includes at least one of quantum key distribution (QKD) session establishment information or corresponding session identification information, The processor identifies the authenticity processing candidate sequence, which includes the evidence acquisition processing candidate or the reference generation processing candidate, based on the quantum key distribution (QKD) session establishment information or the session identification information. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
10. The execution context further includes at least one of quantum computing threat classification information or cryptographic scheme transition condition information as threat information originating from a quantum computer, When the processor detects an update to the quantum computation threat classification information or the cryptographic scheme transition condition information, it regenerates new authenticity execution procedure data based on the updated execution context, associates the identification information of the authenticity execution procedure data before the update with the identification information of the authenticity execution procedure data after the update, and records this in the audit record. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
11. If the processor cannot construct a candidate authenticity processing column that can be connected from the identification acquisition stage to the result recording stage based on the execution context, the appraisal request risk classification information, the authenticity processing candidate table, and the candidate processing connection relationship table, it sets the authenticity determination to a non-executed state and records non-executed state data indicating that non-executed state in the audit record. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
12. The processor performs at least one of the following actions to set the state to non-execution: disabling API call permission information, disabling the execution flag, blocking container startup permission information, or rewriting function call destination control information. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
13. The authenticity determination includes multi-signature authentication based on the alignment or correspondence of at least two authentication elements selected from at least a portion of the identification element and the evidence element. The appraisal and certification system according to claim 1, characterized in that it is a feature of the present invention.
14. At least one of the aforementioned multiple authentication factors is an authentication factor to which third-party authentication has been granted. The authentication and certification system according to claim 13, characterized in that it is a feature of the present invention.
15. On the computer, A genuineness processing candidate table records the candidate identifier, processing stage, request input type, generated output type, and applicable condition information associated with each genuineness processing candidate, A candidate processing connection relationship table that shows whether a connection is possible between the generated output type of the pre-stage authenticity processing candidate and the requested input type of the post-stage authenticity processing candidate, An execution control table indicating whether each authenticity processing candidate is in an executable or non-executable state, Using A process to obtain an execution context that includes identification elements, evidence elements, recording destination, asset type information, and input information related to the appraisal request for the asset to be appraised, A process to calculate appraisal request risk classification information using an artificial intelligence (AI) model based on the input information related to the appraisal request, Based on the execution context, the appraisal request risk classification information, the authenticity processing candidate table, and the candidate processing connection relationship table, a process is performed to identify an authenticity processing candidate column that includes authenticity processing candidates belonging to at least the identification acquisition stage, the evidence acquisition stage, the verification stage, and the result recording stage, and that satisfy the application condition information indicating the conditions for being applied to the authenticity determination of the appraised asset, and to generate authenticity execution procedure data indicating the authenticity processing candidate column, A process that sets the state of the execution control table corresponding to the authenticity processing candidate included in the authenticity execution procedure data to an executable state, and sets the state of the execution control table corresponding to the authenticity processing candidate not included in the authenticity execution procedure data to a non-executable state, A process to perform authenticity determination by executing only the authenticity processing candidates set to the executable state according to the authenticity execution procedure data, A process of recording the identification information of the authenticity execution procedure data and the result of the authenticity determination as an audit record, A program to execute.
16. A computer-based authentication and certification method, Using an authenticity processing candidate table that records candidate identifiers, processing stages, request input types, generated output types, and applicable condition information associated with each authenticity processing candidate, a candidate processing connection relationship table that indicates whether a connection is possible between the generated output type of the preceding authenticity processing candidate and the request input type of the succeeding authenticity processing candidate, and an execution control table that indicates the executable or non-executable state corresponding to each authenticity processing candidate, A step of obtaining an execution context that includes identification elements, evidence elements, recording destination, asset type information, and input information related to the appraisal request for the asset to be appraised, A step of calculating appraisal request risk classification information using an artificial intelligence (AI) model based on the input information relating to the appraisal request, A step of identifying a column of authenticity processing candidates that includes authenticity processing candidates belonging to at least the identification acquisition stage, the evidence acquisition stage, the verification stage, and the result recording stage, and satisfying the application condition information indicating the conditions for being applied to the authenticity determination of the asset subject to appraisal, based on the execution context, the appraisal request risk classification information, the authenticity processing candidate table, and the candidate processing connection relationship table, and generating authenticity execution procedure data that shows the column of authenticity processing candidates, The steps include setting the state of the execution control table corresponding to the authenticity processing candidate included in the authenticity execution procedure data to an executable state, and setting the state of the execution control table corresponding to the authenticity processing candidate not included in the authenticity execution procedure data to a non-executable state, A step of performing authenticity determination by executing only the authenticity processing candidates set to the executable state according to the authenticity execution procedure data, A step of recording the identification information of the authenticity execution procedure data and the result of the authenticity determination as an audit record, A method of authentication and certification characterized by including the following.
Citation Information
Patent Citations
Sheet-like medium, method and device for judging authenticity, and certificate issuing machine
JP2001357377A
Authenticity determination method, authenticity determination device, authenticity determination system, and color two-dimentional code
JP2012141729A
System for determining product genuineness / counterfeit
JP2020035197A
Management of learning history and learning behavior data on block chain
JP2021028824A
Authenticity determination system, authenticity determination method, authenticity determination device, computer program, and method for photographing target medium
JP2025160721A